2019-10-16 11:25:05 +08:00
|
|
|
// SPDX-License-Identifier: GPL-2.0
|
|
|
|
// Copyright (c) 2019 Facebook
|
|
|
|
#include <linux/bpf.h>
|
2019-11-15 02:57:07 +08:00
|
|
|
#include <stdbool.h>
|
2020-01-20 21:06:45 +08:00
|
|
|
#include <bpf/bpf_helpers.h>
|
|
|
|
#include <bpf/bpf_endian.h>
|
2020-03-01 07:11:12 +08:00
|
|
|
#include <bpf/bpf_tracing.h>
|
2019-10-16 11:25:05 +08:00
|
|
|
|
|
|
|
char _license[] SEC("license") = "GPL";
|
|
|
|
struct {
|
|
|
|
__uint(type, BPF_MAP_TYPE_PERF_EVENT_ARRAY);
|
2021-10-01 00:14:56 +08:00
|
|
|
__type(key, int);
|
|
|
|
__type(value, int);
|
2019-10-16 11:25:05 +08:00
|
|
|
} perf_buf_map SEC(".maps");
|
|
|
|
|
|
|
|
#define _(P) (__builtin_preserve_access_index(P))
|
|
|
|
|
|
|
|
/* define few struct-s that bpf program needs to access */
|
|
|
|
struct callback_head {
|
|
|
|
struct callback_head *next;
|
|
|
|
void (*func)(struct callback_head *head);
|
|
|
|
};
|
|
|
|
struct dev_ifalias {
|
|
|
|
struct callback_head rcuhead;
|
|
|
|
};
|
|
|
|
|
|
|
|
struct net_device /* same as kernel's struct net_device */ {
|
|
|
|
int ifindex;
|
|
|
|
struct dev_ifalias *ifalias;
|
|
|
|
};
|
|
|
|
|
|
|
|
typedef struct {
|
|
|
|
int counter;
|
|
|
|
} atomic_t;
|
|
|
|
typedef struct refcount_struct {
|
|
|
|
atomic_t refs;
|
|
|
|
} refcount_t;
|
|
|
|
|
|
|
|
struct sk_buff {
|
|
|
|
/* field names and sizes should match to those in the kernel */
|
|
|
|
unsigned int len, data_len;
|
|
|
|
__u16 mac_len, hdr_len, queue_mapping;
|
|
|
|
struct net_device *dev;
|
|
|
|
/* order of the fields doesn't matter */
|
|
|
|
refcount_t users;
|
|
|
|
unsigned char *data;
|
|
|
|
char __pkt_type_offset[0];
|
2019-11-08 02:09:05 +08:00
|
|
|
char cb[48];
|
2019-10-16 11:25:05 +08:00
|
|
|
};
|
|
|
|
|
2019-11-08 02:09:05 +08:00
|
|
|
struct meta {
|
|
|
|
int ifindex;
|
|
|
|
__u32 cb32_0;
|
|
|
|
__u8 cb8_0;
|
|
|
|
};
|
|
|
|
|
2019-11-24 04:25:04 +08:00
|
|
|
/* TRACE_EVENT(kfree_skb,
|
|
|
|
* TP_PROTO(struct sk_buff *skb, void *location),
|
|
|
|
*/
|
selftests/bpf: Add BPF_PROG, BPF_KPROBE, and BPF_KRETPROBE macros
Streamline BPF_TRACE_x macro by moving out return type and section attribute
definition out of macro itself. That makes those function look in source code
similar to other BPF programs. Additionally, simplify its usage by determining
number of arguments automatically (so just single BPF_TRACE vs a family of
BPF_TRACE_1, BPF_TRACE_2, etc). Also, allow more natural function argument
syntax without commas inbetween argument type and name.
Given this helper is useful not only for tracing tp_btf/fenty/fexit programs,
but could be used for LSM programs and others following the same pattern,
rename BPF_TRACE macro into more generic BPF_PROG. Existing BPF_TRACE_x
usages in selftests are converted to new BPF_PROG macro.
Following the same pattern, define BPF_KPROBE and BPF_KRETPROBE macros for
nicer usage of kprobe/kretprobe arguments, respectively. BPF_KRETPROBE, adopts
same convention used by fexit programs, that last defined argument is probed
function's return result.
v4->v5:
- fix test_overhead test (__set_task_comm is void) (Alexei);
v3->v4:
- rebased and fixed one more BPF_TRACE_x occurence (Alexei);
v2->v3:
- rename to shorter and as generic BPF_PROG (Alexei);
v1->v2:
- verified GCC handles pragmas as expected;
- added descriptions to macros;
- converted new STRUCT_OPS selftest to BPF_HANDLER (worked as expected);
- added original context as 'ctx' parameter, for cases where it has to be
passed into BPF helpers. This might cause an accidental naming collision,
unfortunately, but at least it's easy to work around. Fortunately, this
situation produces quite legible compilation error:
progs/bpf_dctcp.c:46:6: error: redefinition of 'ctx' with a different type: 'int' vs 'unsigned long long *'
int ctx = 123;
^
progs/bpf_dctcp.c:42:6: note: previous definition is here
void BPF_HANDLER(dctcp_init, struct sock *sk)
^
./bpf_trace_helpers.h:58:32: note: expanded from macro 'BPF_HANDLER'
____##name(unsigned long long *ctx, ##args)
Signed-off-by: Andrii Nakryiko <andriin@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200110211634.1614739-1-andriin@fb.com
2020-01-11 05:16:34 +08:00
|
|
|
SEC("tp_btf/kfree_skb")
|
|
|
|
int BPF_PROG(trace_kfree_skb, struct sk_buff *skb, void *location)
|
2019-10-16 11:25:05 +08:00
|
|
|
{
|
|
|
|
struct net_device *dev;
|
|
|
|
struct callback_head *ptr;
|
|
|
|
void *func;
|
|
|
|
int users;
|
|
|
|
unsigned char *data;
|
|
|
|
unsigned short pkt_data;
|
2019-11-08 02:09:05 +08:00
|
|
|
struct meta meta = {};
|
2019-10-16 11:25:05 +08:00
|
|
|
char pkt_type;
|
2019-11-08 02:09:05 +08:00
|
|
|
__u32 *cb32;
|
|
|
|
__u8 *cb8;
|
2019-10-16 11:25:05 +08:00
|
|
|
|
|
|
|
__builtin_preserve_access_index(({
|
|
|
|
users = skb->users.refs.counter;
|
|
|
|
data = skb->data;
|
|
|
|
dev = skb->dev;
|
|
|
|
ptr = dev->ifalias->rcuhead.next;
|
|
|
|
func = ptr->func;
|
2019-11-08 02:09:05 +08:00
|
|
|
cb8 = (__u8 *)&skb->cb;
|
|
|
|
cb32 = (__u32 *)&skb->cb;
|
2019-10-16 11:25:05 +08:00
|
|
|
}));
|
|
|
|
|
2019-11-08 02:09:05 +08:00
|
|
|
meta.ifindex = _(dev->ifindex);
|
|
|
|
meta.cb8_0 = cb8[8];
|
|
|
|
meta.cb32_0 = cb32[2];
|
|
|
|
|
2019-11-02 07:18:02 +08:00
|
|
|
bpf_probe_read_kernel(&pkt_type, sizeof(pkt_type), _(&skb->__pkt_type_offset));
|
2019-10-16 11:25:05 +08:00
|
|
|
pkt_type &= 7;
|
|
|
|
|
|
|
|
/* read eth proto */
|
2019-11-02 07:18:02 +08:00
|
|
|
bpf_probe_read_kernel(&pkt_data, sizeof(pkt_data), data + 12);
|
2019-10-16 11:25:05 +08:00
|
|
|
|
|
|
|
bpf_printk("rcuhead.next %llx func %llx\n", ptr, func);
|
|
|
|
bpf_printk("skb->len %d users %d pkt_type %x\n",
|
|
|
|
_(skb->len), users, pkt_type);
|
|
|
|
bpf_printk("skb->queue_mapping %d\n", _(skb->queue_mapping));
|
|
|
|
bpf_printk("dev->ifindex %d data %llx pkt_data %x\n",
|
2019-11-08 02:09:05 +08:00
|
|
|
meta.ifindex, data, pkt_data);
|
|
|
|
bpf_printk("cb8_0:%x cb32_0:%x\n", meta.cb8_0, meta.cb32_0);
|
2019-10-16 11:25:05 +08:00
|
|
|
|
2019-11-08 02:09:05 +08:00
|
|
|
if (users != 1 || pkt_data != bpf_htons(0x86dd) || meta.ifindex != 1)
|
2019-10-16 11:25:05 +08:00
|
|
|
/* raw tp ignores return value */
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
/* send first 72 byte of the packet to user space */
|
|
|
|
bpf_skb_output(skb, &perf_buf_map, (72ull << 32) | BPF_F_CURRENT_CPU,
|
2019-11-08 02:09:05 +08:00
|
|
|
&meta, sizeof(meta));
|
2019-10-16 11:25:05 +08:00
|
|
|
return 0;
|
|
|
|
}
|
2019-11-15 02:57:07 +08:00
|
|
|
|
2021-05-07 13:41:15 +08:00
|
|
|
struct {
|
2019-11-15 02:57:07 +08:00
|
|
|
bool fentry_test_ok;
|
|
|
|
bool fexit_test_ok;
|
2021-05-07 13:41:15 +08:00
|
|
|
} result = {};
|
2019-11-15 02:57:07 +08:00
|
|
|
|
selftests/bpf: Add BPF_PROG, BPF_KPROBE, and BPF_KRETPROBE macros
Streamline BPF_TRACE_x macro by moving out return type and section attribute
definition out of macro itself. That makes those function look in source code
similar to other BPF programs. Additionally, simplify its usage by determining
number of arguments automatically (so just single BPF_TRACE vs a family of
BPF_TRACE_1, BPF_TRACE_2, etc). Also, allow more natural function argument
syntax without commas inbetween argument type and name.
Given this helper is useful not only for tracing tp_btf/fenty/fexit programs,
but could be used for LSM programs and others following the same pattern,
rename BPF_TRACE macro into more generic BPF_PROG. Existing BPF_TRACE_x
usages in selftests are converted to new BPF_PROG macro.
Following the same pattern, define BPF_KPROBE and BPF_KRETPROBE macros for
nicer usage of kprobe/kretprobe arguments, respectively. BPF_KRETPROBE, adopts
same convention used by fexit programs, that last defined argument is probed
function's return result.
v4->v5:
- fix test_overhead test (__set_task_comm is void) (Alexei);
v3->v4:
- rebased and fixed one more BPF_TRACE_x occurence (Alexei);
v2->v3:
- rename to shorter and as generic BPF_PROG (Alexei);
v1->v2:
- verified GCC handles pragmas as expected;
- added descriptions to macros;
- converted new STRUCT_OPS selftest to BPF_HANDLER (worked as expected);
- added original context as 'ctx' parameter, for cases where it has to be
passed into BPF helpers. This might cause an accidental naming collision,
unfortunately, but at least it's easy to work around. Fortunately, this
situation produces quite legible compilation error:
progs/bpf_dctcp.c:46:6: error: redefinition of 'ctx' with a different type: 'int' vs 'unsigned long long *'
int ctx = 123;
^
progs/bpf_dctcp.c:42:6: note: previous definition is here
void BPF_HANDLER(dctcp_init, struct sock *sk)
^
./bpf_trace_helpers.h:58:32: note: expanded from macro 'BPF_HANDLER'
____##name(unsigned long long *ctx, ##args)
Signed-off-by: Andrii Nakryiko <andriin@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200110211634.1614739-1-andriin@fb.com
2020-01-11 05:16:34 +08:00
|
|
|
SEC("fentry/eth_type_trans")
|
|
|
|
int BPF_PROG(fentry_eth_type_trans, struct sk_buff *skb, struct net_device *dev,
|
|
|
|
unsigned short protocol)
|
2019-11-15 02:57:07 +08:00
|
|
|
{
|
|
|
|
int len, ifindex;
|
|
|
|
|
|
|
|
__builtin_preserve_access_index(({
|
|
|
|
len = skb->len;
|
|
|
|
ifindex = dev->ifindex;
|
|
|
|
}));
|
|
|
|
|
|
|
|
/* fentry sees full packet including L2 header */
|
|
|
|
if (len != 74 || ifindex != 1)
|
|
|
|
return 0;
|
|
|
|
result.fentry_test_ok = true;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
selftests/bpf: Add BPF_PROG, BPF_KPROBE, and BPF_KRETPROBE macros
Streamline BPF_TRACE_x macro by moving out return type and section attribute
definition out of macro itself. That makes those function look in source code
similar to other BPF programs. Additionally, simplify its usage by determining
number of arguments automatically (so just single BPF_TRACE vs a family of
BPF_TRACE_1, BPF_TRACE_2, etc). Also, allow more natural function argument
syntax without commas inbetween argument type and name.
Given this helper is useful not only for tracing tp_btf/fenty/fexit programs,
but could be used for LSM programs and others following the same pattern,
rename BPF_TRACE macro into more generic BPF_PROG. Existing BPF_TRACE_x
usages in selftests are converted to new BPF_PROG macro.
Following the same pattern, define BPF_KPROBE and BPF_KRETPROBE macros for
nicer usage of kprobe/kretprobe arguments, respectively. BPF_KRETPROBE, adopts
same convention used by fexit programs, that last defined argument is probed
function's return result.
v4->v5:
- fix test_overhead test (__set_task_comm is void) (Alexei);
v3->v4:
- rebased and fixed one more BPF_TRACE_x occurence (Alexei);
v2->v3:
- rename to shorter and as generic BPF_PROG (Alexei);
v1->v2:
- verified GCC handles pragmas as expected;
- added descriptions to macros;
- converted new STRUCT_OPS selftest to BPF_HANDLER (worked as expected);
- added original context as 'ctx' parameter, for cases where it has to be
passed into BPF helpers. This might cause an accidental naming collision,
unfortunately, but at least it's easy to work around. Fortunately, this
situation produces quite legible compilation error:
progs/bpf_dctcp.c:46:6: error: redefinition of 'ctx' with a different type: 'int' vs 'unsigned long long *'
int ctx = 123;
^
progs/bpf_dctcp.c:42:6: note: previous definition is here
void BPF_HANDLER(dctcp_init, struct sock *sk)
^
./bpf_trace_helpers.h:58:32: note: expanded from macro 'BPF_HANDLER'
____##name(unsigned long long *ctx, ##args)
Signed-off-by: Andrii Nakryiko <andriin@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200110211634.1614739-1-andriin@fb.com
2020-01-11 05:16:34 +08:00
|
|
|
SEC("fexit/eth_type_trans")
|
|
|
|
int BPF_PROG(fexit_eth_type_trans, struct sk_buff *skb, struct net_device *dev,
|
|
|
|
unsigned short protocol)
|
2019-11-15 02:57:07 +08:00
|
|
|
{
|
|
|
|
int len, ifindex;
|
|
|
|
|
|
|
|
__builtin_preserve_access_index(({
|
|
|
|
len = skb->len;
|
|
|
|
ifindex = dev->ifindex;
|
|
|
|
}));
|
|
|
|
|
|
|
|
/* fexit sees packet without L2 header that eth_type_trans should have
|
|
|
|
* consumed.
|
|
|
|
*/
|
2019-11-24 04:25:04 +08:00
|
|
|
if (len != 60 || protocol != bpf_htons(0x86dd) || ifindex != 1)
|
2019-11-15 02:57:07 +08:00
|
|
|
return 0;
|
|
|
|
result.fexit_test_ok = true;
|
|
|
|
return 0;
|
|
|
|
}
|